Do not open a public issue for security problems. Use GitHub's "Report a vulnerability" (Security → Advisories) on this repository, or contact the maintainers privately through the contact information on the repository page. You will get an acknowledgement within a week.
Please include: affected version/commit, reproduction steps or a proof of concept, and your assessment of impact.
Anything that could harm users of this tool, especially:
- credential leakage or exfiltration (the tool must send the user's
Consumer Key/Secret only to
https://ops.epo.org/3.2/auth/accesstoken); - writes outside the documented locations (
~/.epo/, user-specified output files); - injection through search results / API responses;
- dependency or build-process compromises.
These properties are intentional and protected:
- No telemetry. The tool collects nothing; the only outbound traffic is
to
ops.epo.org. - Credentials stay local. Stored at
~/.epo/ops_config.json, never logged, never transmitted except to the EPO auth endpoint. - No subprocess, no eval. The package never shells out and never dynamically evaluates strings.
- Single runtime dependency (
requests).
A regression against any of these is a security bug — please report it.